Please add some widget in Offcanvs Sidebar
From public sector to private, from mutual insurer to museum: every engagement combines architecture, cloud and cybersecurity. Out of respect for confidentiality, our references are presented by sector, without naming our clients.
Migration of email and users to a hybrid Microsoft 365 cloud architecture, rebuilding of the IT system on a resilient multi-site vSphere platform with a business continuity plan, network segmentation through a next-generation firewall cluster, VPN access with MFA, Centreon/Wazuh monitoring, EDR with an outsourced SOC and immutable backups.
→ A modernised, resilient IT system, ready to meet insurance partners’ audits.
Carve-out of a subsidiary from a hybrid tenant to a cloud-native Azure / Microsoft 365 tenant: tenant-to-tenant migration of data (email, OneDrive, Teams, SharePoint), telephony switch-over to Teams Phone, industrialised workstation deployment via Intune and AutoPilot, hardening of the Azure and Defender environment.
→ A controlled switch-over with no service disruption, and an industrialised workstation build.
Carve-out from the group tenant and migration to a new hybrid Microsoft 365 infrastructure, hardening and reinforcement of security policies, Intune MDM (Corporate and BYOD), rollout of an ITIL-aligned ITSM, securing of the AWS cloud platform (IAM, MFA, WAF), Fortinet firewalls and partner VPNs.
→ An autonomous, secure subsidiary aligned with the group’s standards.
Audit of the Microsoft 365 configuration and reinforcement of access through Entra Conditional Access, infrastructure vulnerability assessment, drafting of an audit report and presentation to the IT department and management, prioritised remediation plan.
→ A reduced attack surface and teams made aware of best practice.
Deployment of a unified tool for managing and securing workstations and servers, industrialisation of the imaging and deployment process for user workstations and factory stations.
→ A consistent, controlled estate deployed at scale.
Responsibility for the infrastructure and security of a critical, multi-site information system: operations, evolution projects (network, systems, virtualisation, storage, ToIP), annual security audits conducted with ANSSI-certified partners, compliance with the group’s information security policy, migration of critical applications to AWS and Azure cloud, disaster recovery site.
→ A sensitive information system kept in service continuity and under control.
Implementation of a tiered administration model isolating critical resources (Tier 0), with hardened privileged access workstations (PAW), strong authentication (MFA) and mandatory jump-host access through bastions. Segmentation of administration traffic and rigorous management of privileged accounts.
→ A fully compartmentalised administration model, aligned with ANSSI best practice.
Deployment of a Mobile Threat Defense (MTD) solution providing real-time protection for devices across the three threat vectors — applications, network and system: blocking of malicious or intrusive applications, network attacks and phishing, and monitoring of device integrity and compliance. Integration with fleet management (UEM/MDM) for automated remediation and conditional access, while respecting user privacy and GDPR.
→ A mobile fleet continuously protected against malicious applications, phishing and network attacks, while safeguarding staff privacy.